Subject: Re: X font library vulnerability vs. pkgsrc
To: Charles M. Hannum <abuse@spamalicious.com>
From: Steven M. Bellovin <smb@research.att.com>
List: netbsd-users
Date: 10/09/2003 16:56:18
In message <200310092047.50584.abuse@spamalicious.com>, "Charles M. Hannum" wri
tes:
>On Thursday 09 October 2003 08:38 pm, Steve Bellovin wrote:
>> It isn't clear to me from the vulnerability notice just how much needs
>> to be rebuilt. Just some shared libraries? Executables, too? If the
>> latter, what about pkgsrc applications that use X?
>
>Prior to -current as of several days ago, libFS was only a static library, so
>you'd need to rebuild anything that uses it (including the X server, I
>think).
>
Which means that a lot of pkgsrc needs to be rebuilt. Anyone have any
nice scripts for determining exactly what? (And the advisory should be
amended to note the issue.)
--Steve Bellovin, http://www.research.att.com/~smb